VDB
GHSA-2p76-gc46-5fvc
GHSA-2p76-gc46-5fvc
PUBLISHED
CVSS 8.199999809265137 HIGH
GeoNetwork affected by XML External Entity (XXE) processing vulnerability in WFS indexing REST API endpoint
Risk Scores
CVSS v3.1
8.199999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Maven | org.geonetwork-opensource:gn-wfsfeature-harvester | 4.2.0, 4.4.0, 4.4.0 |
| Maven | org.geonetwork-opensource:gn-web-app | 4.4.0, 4.2.0, 4.4.0 |
| Maven | org.geonetwork-opensource:gn-web-app |
Timeline
- Jun 10, 2025 CVE Published
- Feb 4, 2026 CVE Updated
References
- https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-2p76-gc46-5fvc url
- https://github.com/geotools/geotools/security/advisories/GHSA-826p-4gcg-35vw url
- https://github.com/geonetwork/core-geonetwork/pull/8757 url
- https://github.com/geonetwork/core-geonetwork/pull/8803 url
- https://github.com/geonetwork/core-geonetwork/pull/8812 url
- https://github.com/geonetwork/core-geonetwork package
- GitHub Advisory GHSA-2p76-gc46-5fvc vendor-advisory